Artificial Intelligence
13 Jul 2026

AI risk categories explained simply: the 4 levels

Luca Blöcher
Reading time:
11
minutes
Diverse office team at a whiteboard and laptop classifying AI applications into the four risk categories
Table of contents

The four risk categories of the EU AI Act at a glance

The EU AI Act – the AI Regulation (EU) 2024/1689 – classifies every AI application into one of four levels according to its risk: unacceptable risk (prohibited practices), high risk, limited risk with transparency obligations, and minimal risk. The higher the level, the stricter the obligations. For companies, classification is the first step of any AI compliance, because it determines which rules apply in the first place. This article explains the four levels with examples, names the relevant provision for each level, and puts into context what they mean for use in the company. The basis is the text of the regulation; as of September 4, 2026. For the timeline: the EU AI Act entered into force on August 1, 2024, and has largely applied since August 2, 2026 – the prohibitions of level 1 have already applied since February 2, 2025.

The term "four risk categories" is the established presentation of the European Commission and the specialist literature – not a literal term of the regulation's text. There, the individual rules are spread across Articles 5, 6, and 50 and Annex III. General-purpose AI models such as large language models additionally form a separate regulatory track (Art. 51 et seq.) outside this four-level scheme; more on this below. The AI glossary provides an overview of the associated basic terms.

The following overview orders the four levels from the highest to the lowest risk:

LevelRisk categoryLegal basisTypical examplesPrinciple
1 (highest)Unacceptable riskArt. 5Social scoring, emotion recognition in the workplaceProhibited
2High riskArt. 6 in conjunction with Annex III (or Annex I)AI in recruiting, creditworthiness assessmentPermitted, but extensive obligations
3Limited riskArt. 50Chatbots, AI-generated images and videosTransparency and labeling obligation
4 (lowest)Minimal riskno special obligationsSpam filters, autocorrectFree to use

Level 1: Unacceptable risk – prohibited practices

AI applications with unacceptable risk are prohibited under Art. 5 of the EU AI Act – and have been since February 2, 2025, earlier than most of the regulation. They concern applications that are considered fundamentally incompatible with the fundamental rights and values of the European Union. For companies, this level is above all an exclusion list: such systems may neither be offered nor used.

Under Art. 5, the prohibited practices include, among others:

  • social scoring, i.e. the evaluation of people on the basis of their social behavior with detrimental consequences;
  • the use of manipulative or deceptive techniques that influence people's behavior subliminally and to their detriment;
  • the exploitation of the vulnerability of certain persons – for example due to age, disability, or economic situation;
  • emotion recognition in the workplace and in educational institutions – except for medical or safety reasons;
  • the untargeted scraping of facial images from the internet or from surveillance cameras to build facial recognition databases;
  • biometric categorization in order to infer sensitive characteristics such as ethnic origin, political opinion, or sexual orientation;
  • predictive risk assessment of whether a person will commit a criminal offense, based solely on profiling or personality traits;
  • real-time remote biometric identification in publicly accessible spaces for law enforcement purposes, which is only permitted in narrowly limited exceptional cases.

The European Commission published its own guidelines on the interpretation of these prohibitions in early 2025; they are not legally binding but reflect the authorities' reading. For operational practice, it is above all worth taking a look at your own HR function and security technology: it is precisely there that emotion or behavior analyses sometimes appear unnoticed in purchased tools. Violations of the prohibitions of Art. 5 are set at the highest level in the regulation's penalty framework (Art. 99 (3)); the specific calculation of fines is a matter for the individual case and is deliberately not presented here as a core statement. What matters first is to rule out such applications from the outset.

Level 2: High risk – the strictest obligations

High-risk AI is permitted but is subject to the most extensive requirements of the regulation. Under Art. 6, two groups are considered high-risk: AI as a safety component in products that are already regulated (Annex I) and AI in the sensitive areas of use of Annex III. For most companies, Annex III is the practically relevant point of reference.

Annex III names eight areas in which AI systems are classified as high-risk:

  1. biometrics (no. 1), for example remote biometric identification outside the prohibited cases;
  2. critical infrastructure (no. 2), where AI serves as a safety component;
  3. education and vocational training (no. 3), for example in admission or the evaluation of exams;
  4. employment and HR management (no. 4), for example AI for selecting applicants or for promotion and termination decisions;
  5. access to essential private and public services (no. 5) – this includes the creditworthiness assessment of natural persons (no. 5 lit. b), with the exception of pure fraud detection;
  6. law enforcement (no. 6);
  7. migration, asylum, and border control (no. 7);
  8. administration of justice and democratic processes (no. 8).

One exception is important: under Art. 6 (3), a system listed in Annex III is not automatically considered high-risk if it does not pose a significant risk to health, safety, or fundamental rights – for example because it only performs a narrowly defined procedural task or merely prepares a human assessment. Anyone who relies on this exception must document the assessment. Otherwise, the regulation requires providers of high-risk AI to fulfill a whole bundle of obligations, each with its own legal reference:

  • a continuous risk management system over the entire life cycle (Art. 9);
  • requirements for the quality and representativeness of the training, validation, and test data in order to limit bias (Art. 10);
  • technical documentation that makes it possible to demonstrate conformity (Art. 11);
  • automatic logging of events over the period of operation (Art. 12);
  • transparency and the provision of information that allows the deployer to use the system appropriately (Art. 13);
  • arrangements for effective human oversight (Art. 14);
  • an appropriate level of accuracy, robustness, and cybersecurity (Art. 15).

In addition, there is a conformity assessment and the CE marking before such a system is placed on the market. Deployers of high-risk systems also have their own, leaner obligations (Art. 26): they must use the system in accordance with the instructions for use, ensure human oversight by suitable persons, and keep the logs. When a system is used by public bodies or in certain areas of fundamental rights, a fundamental rights impact assessment may additionally be required (Art. 27).

As for the deadlines, a new status has applied since summer 2026. The Digital Omnibus Regulation (Regulation (EU) 2026/1744), published on July 24, 2026, and in force since July 27, 2026, has postponed the application of the obligations for high-risk systems under Annex III from August 2, 2026, to December 2, 2027, and for AI in products that are already regulated (Annex I) to August 2, 2028. For systems placed on the market before August 2, 2026, the machine-readable marking under Art. 50 (2) only applies from December 2, 2026. The article Digital Omnibus: What is changing in the EU AI Act puts the details into context; before planning, the currently applicable text of the regulation should be checked.

Level 3: Limited risk – creating transparency

Under Art. 50, certain AI systems with limited risk are subject above all to transparency obligations. The basic idea: people should know when they are dealing with AI. These obligations have applied since the main date of application on August 2, 2026.

In practice, this means, for example: chatbots and voice assistants must make it recognizable that users are communicating with a machine; AI-generated or AI-edited images, audio, and videos – such as deepfakes – must be labeled as artificially generated; and anyone who uses systems for emotion recognition or biometric categorization must inform the persons concerned. These requirements are considerably leaner than for high-risk AI but affect many everyday applications in customer contact and marketing. For companies that use generative AI in external communication, this level is therefore often the most relevant in practice – and comparatively easy to fulfill with clear notices and internal rules. Under Art. 50, AI-generated content must also be labeled in a machine-readable format so that downstream platforms and recipients can also technically recognize synthetic media as such.

Level 4: Minimal risk – the normal case

The vast majority of AI applications fall into the minimal risk level and are not subject to any special obligations under the regulation. These include, for example, spam filters, AI in spelling aids, or recommendation functions. Their use is generally free; however, the regulation expressly welcomes voluntary codes of conduct (Art. 95).

What is important: even with minimal risk, other laws remain applicable – in particular the General Data Protection Regulation (GDPR) as soon as personal data is processed. Assignment to the "minimal" level therefore does not exempt you from data protection, copyright, or employment law obligations. And it is not set in stone: if the same technology is used for a more sensitive purpose, the classification can tip into a higher level.

Special case: general-purpose AI models

In addition to the four-level scheme, the regulation has a separate category: general-purpose AI models (General-Purpose AI, Art. 51 et seq.), which include large language models. They are not classified according to the four risk categories but follow their own provider obligations – for example on technical documentation, copyright, and a summary of the training data. Additional requirements apply to models with "systemic risk". These rules have already applied since August 2, 2025. Anyone who merely uses such a model in their own application does not thereby automatically become a model provider themselves – the specific role in the individual case remains decisive.

How to classify your AI systems correctly

Classification begins with two questions: What role does your company play, and what is the system used for? Anyone who develops an AI system and offers it under their own name is a provider (Art. 3 no. 3) and bears the most far-reaching obligations. Anyone who uses a purchased system under their own responsibility is a deployer (Art. 3 no. 4) – this applies to most companies. Deployers have their own, leaner obligations, such as use in line with the intended purpose and human oversight for high-risk systems. Only the specific intended purpose determines the risk category, not the technology alone.

Classification is also not a one-off act: if a system is used for a new purpose, its risk category can change. A maintained register of the AI systems in use helps to keep track. Since the EU AI Act was last amended by Regulation (EU) 2026/1744 in July 2026 and national supervision in Germany has rested with the Bundesnetzagentur (Federal Network Agency) since July 29, 2026 (Section 2 (1) KI-MIG), a professional or legal review is advisable for specific individual cases.

Classification in three steps

For getting started, a simple approach has proven itself that manages without legal detail and is nevertheless robust:

  1. Inventory: Record all AI systems that are actually used in the company – including purchased functions in standard software and tools introduced independently by individual teams.
  2. Clarify role and purpose: For each system, record whether you are a provider or a deployer and what specific intended purpose it serves. Only the purpose determines the risk category.
  3. Classify and document: Assign each system to one of the four levels and record the reasoning. This documentation is at the same time the basis for deriving obligations and training needs.

This approach does not replace legal advice in the individual case, but it creates a robust overview and quickly shows where a closer look is needed.

Common misconceptions about the risk categories

Several false assumptions persist around the risk categories that lead to wrong conclusions in practice. Three particularly widespread ones:

  • "If we only buy AI, the AI Act does not affect us." Deployers of purchased systems also have obligations – from transparency to human oversight in high-risk applications. The role of provider can also shift, for example if a system is substantially modified or passed on under one's own name.
  • "High-risk means dangerous and prohibited." High-risk AI is expressly permitted. The term only describes that the application must meet increased requirements – not that it is prohibited. Only the practices of level 1 are prohibited.
  • "A chatbot is automatically high-risk." Most chatbots fall under limited risk and above all trigger the labeling obligation under Art. 50. A system only becomes high-risk through its area of use under Annex III, not through the technology alone.

The EU AI Act provides for a tiered penalty framework for violations (Art. 99); the specific amounts of fines depend on the nature and severity of the violation and are deliberately not presented here as a core statement. For operational practice, what counts first is correct classification – it is the basis of all further obligations.

Why the risk categories are a training topic

Anyone who knows the four risk categories can assess in everyday work which AI application is harmless and where particular care applies. Precisely this ability to classify is part of the AI literacy that Art. 4 of the regulation requires of providers and deployers: employees should understand the opportunities and risks of the systems in use. The article on the content of AI training shows which content such training sensibly covers; the article on AI hallucinations explains how typical error patterns of generative systems can be classified. A note on our own behalf: For companies that want to impart this basic knowledge in a structured and verifiable way, Bridgly offers ready-made, digital mandatory AI training courses whose completion can be documented traceably via the learning platform, provided that the participation records are maintained and retained. Further articles are collected in the Artificial Intelligence topic hub.

FAQ

Which four risk categories does the EU AI Act have?
The EU AI Act distinguishes between unacceptable risk (prohibited practices under Art. 5), high risk (Art. 6 and Annex III), limited risk with transparency obligations (Art. 50), and minimal risk without special obligations. The classification follows the harm that an application can cause. General-purpose AI models form a separate regulatory track.

Is high-risk AI prohibited?
No. High-risk AI is permitted but must meet extensive requirements, such as risk management, data quality, technical documentation, and human oversight. Only the practices of the highest level under Art. 5 are prohibited; they have already been banned since February 2, 2025.

Who decides which risk category a system falls into?
What is decisive is the specific intended purpose and the company's role as provider or deployer. The same system can be classified differently depending on how it is used. In cases of doubt, a professional or legal review of the individual case is advisable.

From when do the obligations for high-risk AI apply?
For stand-alone high-risk systems under Annex III from December 2, 2027, and for high-risk AI in regulated products under Annex I from August 2, 2028. The postponement was brought about by the Digital Omnibus Regulation (EU) 2026/1744, which has been in force since July 27, 2026.

Sources

More blog posts

Insights into the future of digital learning, with a focus on AI, compliance, and modern training solutions. Discover the latest posts and articles to gain practical insights into legally compliant, efficient, and automated corporate training.

Note: Some text, images, and videos on this website were generated using artificial intelligence.
All content is for informational purposes and has been carefully reviewed from a journalistic perspective, but does not claim to be exhaustive or legally binding.